CVE-2026-41458

OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. Attackers can flood the DAAP /login endpoint with concurrent requests to trigger a remote denial of service condition without requiring authentication.
CVSS

No CVSS.

Configurations

No configuration.

History

22 Apr 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-22 03:16

Updated : 2026-04-22 21:21


NVD link : CVE-2026-41458

Mitre link : CVE-2026-41458

CVE.ORG link : CVE-2026-41458


JSON object : View

Products Affected

No product.

CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')